USENIX Security2021Top-tier venue
Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android Applications
Marten Oltrogge, Nicolas Huaman, Sabrina Amft, Yasemin Acar, Michael Backes, Sascha Fahl
Abstract
Android applications have a long history of being vulnerable to man-in-the-middle attacks due to insecure custom TLS certificate validation implementations. To resolve this, Google deployed the Network Security Configuration (NSC), a configuration-based approach to increase custom certificate validation logic security, and implemented safeguards in Google Play to block insecure applications. In this paper, we perform a large-scale in-depth investigation of the effectiveness of these countermeasures: First, we investigate the security of 99,212 NSC settings files in 1,335,322 Google Play apps using static code and manual analysis techniques. We find that 88.87% of the apps using custom NSC settings downgrade security compared to the default settings, and only 0.67% implement certificate pinning. Second, we penetrate Google Play's protection mechanisms by trying to publish apps that are vulnerable to man-in-the-middle attacks. In contrast to official announcements by Google, we found that Play does not effectively block vulnerable apps. Finally, we performed a static code analysis study of 15,000 apps and find that 5,511 recently published apps still contain vulnerable certificate validation code. Overall, we attribute most of the problems we find to insufficient support for developers, missing clarification of security risks in official documentation, and inadequate security checks for vulnerable applications in Google Play.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext efafdcd9-797d-4318-8f0d-40ebd5989bffCited by top-tier papers11
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
- Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android AppsTrung Tin Nguyen, Michael Backes, Ben StockCCS 2022 · 32 citations
- An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy PerspectivesHanyang Guo, Hong-Ning Dai, Xiapu Luo, Zibin Zheng et al.ICSE 2024 · 17 citations
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause et al.CCS 2023 · 14 citations
- Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS GalaxySajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan et al.USENIX Security 2024 · 7 citations
Builds on7
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky et al.S&P 2017 · 293 citations
- A Stitch in Time: Supporting Android Developers in WritingSecure CodeDuc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes et al.CCS 2017 · 125 citations
- The Rise of the Citizen Developer: Assessing the Security Impact of Online App GeneratorsMarten Oltrogge, Erik Derr, Christian Stransky, Yasemin Acar et al.S&P 2018 · 69 citations
- TrustBase: An Architecture to Repair and Strengthen Certificate-based AuthenticationMark O'Neill, Scott Heidbrink, Scott Ruoti, Jordan Whitehead et al.USENIX Security 2017 · 30 citations
Related papers
- Towards HTTPS Everywhere on Android: We Are Not There YetAndrea Possemato, Yanick FratantonioUSENIX Security 2020
- Assessing certificate validation user interfaces of WPA supplicantsKailong Wang, Yuwei Zheng, Qing Zhang, Guangdong Bai et al.MobiCom 2022 · 10 citations
- Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate ValidationWoonghee Lee, Junbeom Hur, Hyunsoo KwonCCS 2025
- Detecting and Measuring Misconfigured Manifests in Android AppsYuqing Yang, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson et al.CCS 2022 · 11 citations
- Vulnerable Implicit Service: A RevisitLingguang Lei, Yi He, Kun Sun, Jiwu Jing et al.CCS 2017 · 5 citations
